|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2009-26

Adobe Reader and Acrobat Remote Code Execution Vulnerability

Original Issue Date: October 14, 2009

Severity Rating: High

Affected Softwares

  • Adobe Reader 9.1.3 and earlier versions
  • Adobe Acrobat 9.1.3 and earlier versions

Overview

A vulnerability has been reported in Adobe Reader and Acrobat, which could allow a remote attacker to execute an arbitrary code or causes denial of service condition.

Description

This vulnerability is caused due to an unspecified error in parsing PDF file in Adobe Reader and Acrobat. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted PDF file resulting in arbitrary code execution in the context of the user running the affected application or cause denial of service (DoS) condition.

Workarounds

  • Disable JavaScript until vendor fixes available.
  • Do not open PDF documents received from untrusted sources.
  • Enable Data Execution Prevention (DEP) on Windows Vista.

Vendor Information

Adobe
http://www.adobe.com/support/security/bulletins/apsb09-15.html

CVE Name
CVE-2009-3459

References

Adobe
http://www.adobe.com/support/security/bulletins/apsb09-15.html

http://blogs.adobe.com/psirt

SecurityFocus
http://www.securityfocus.com/bid/36600/

SecurityTracker
http://www.securitytracker.com/alerts/2009/Oct/1022998.html

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

10-Jul-2011